<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <p><br>
    </p>
    <br>
    <div class="moz-cite-prefix">On 10/18/16 9:32 PM, Tom Zeller wrote:<br>
    </div>
    <blockquote
cite="mid:CAMNmQDSej-VAK63pdetjOMaw6uE7CdR9pC286KVY+VNSWSBzgQ@mail.gmail.com"
      type="cite">
      <blockquote type="cite">
        <pre wrap="">At this point, I'd propose we do it for a 3.4.
</pre>
      </blockquote>
      <pre wrap="">
Agree, but perhaps we should bundle updating HC with Java 8 and Spring
Framework 5, which would be more like 4.0.</pre>
    </blockquote>
    <br>
    We certainly can do that.  I've obviously not been in a big hurry to
    upgrade HC.  I'm not a believer in upgrading to the newest, shiniest
    version of something just because it's new and shiny.  In the
    absence of any known security vulnerabilities or functionality bugs,
    I don't think it's urgent...<br>
    <br>
    <blockquote
cite="mid:CAMNmQDSej-VAK63pdetjOMaw6uE7CdR9pC286KVY+VNSWSBzgQ@mail.gmail.com"
      type="cite">
      <pre wrap=""> Seems like Java and SF are
less concerning than HC, 
</pre>
    </blockquote>
    <br>
    ... OTOH, I don't know for sure that is true.  HC is critical to us
    and we make use of various advanced bits, but Java and Spring are
    "bigger", so it's a tossup.  When I get some time to actually look
    in detail at HC 4.5, it may be that my initial concerns were
    unfounded and upgrading will be no big deal.<br>
    <br>
    IIRC the main red flag was I think it goes out and attempts to
    automatically download some public suffix stuff, but hopefully
    there's an easy way to turn that off.<br>
  </body>
</html>